Skip to content

auth status reports success after selected-domain validation fails #112

Description

@justinhelmer

Problem

polylane auth status treats the existence of a locally unexpired credential as authenticated even when /v1/auth/whoami rejects that credential on the selected API domain or cannot be reached. The command catches every validation error and then unconditionally prints authenticated: true.

This is reproducible with an unexpired production OAuth credential in the single global ~/.polylane/credentials.json while selecting POLYLANE_API_DOMAIN=api.baseberry.cc: the UAT identity request returns 401, but status reports success. That is unsafe for cross-environment validation and automation.

Required behavior

  • Remote identity validation against the selected API domain is authoritative.
  • A 401 or otherwise invalid credential reports unauthenticated with auth-class exit/error semantics and a useful sign-in hint.
  • Network, timeout, malformed-response, and server failures remain distinguishable from invalid credentials; they must not claim either authenticated success or credential invalidity without evidence.
  • A successful same-environment validation preserves the current status details.
  • Preserve credential storage/precedence, OAuth refresh behavior, API-key and MCP scope enforcement, and installer behavior from coreplanelabs/polylanedotcom#111.
  • Documentation must describe OAuth client overrides as environment-bound without inventing non-production client IDs or secrets.

Proof required

Red-first regressions for:

  1. unexpired credential issued for another environment,
  2. selected-domain 401,
  3. network failure/unknown state,
  4. successful same-environment baseline.

Update the covering living spec/docs in the same PR.

Context

Related but not completion of this defect: #34 and #36 cover runtime OAuth client overrides; coreplanelabs/nominal#1165 records the separate UAT client-provisioning gap. This issue must introduce no OAuth client provisioning, credentials, configuration changes, login retries, or deployment side effects.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions